Skip to main content

Creation of MDM Server in Apple Business Manager

  1. Login to Apple Business Manager

alt text

  1. Go to Devices and then choose Management. Then the below screen will appear as follows:

alt text

  1. Click Add

  2. Upon clicking on the Add, the below screen will appear in which the MDM Service Name should be provided.

alt text

note

Enable Allow this service to release devices if required. This option is to enable the configuration to release the devices from the created MDM server if required.

  1. After providing the Service Name, click Upload Certificate. Upload the .pem certificate which was downloaded from the SureMDM server. Then click Next

alt text

note

The .pem certificate should be downloaded from SureMDM Web Console > Account Settings > iOS/iPad/MacOS Settings > ADE > ADE Server tab > Upload Token > Download

  1. In this step, click Download Service Token to download your service token and click Done.

alt text

Then the token will get downloaded to your local drive.

  1. Once the MDM Server is created, then it will get listed in the Services tab under the Management Services section.

alt text

Then the token will get downloaded to your local drive.

Uploading the Server Token in SureMDM

1. In the SureMDM Console, browse and upload the Server Token (which was downloaded from Apple Business Manager) in the Server Token field using the upload icon.

alt text

2. After the server token upload, click Next to Profile Assignment

SettingDescription
Enable Profile MappingIf checked, configured ADE profile will be assigned for macOS devices during enrollment.
Profile Assignment Scope
All Devices - Select this option to assign an ADE profile to all devices enrolling through this ADE Server for the selected platform.
Device-specific Assignment - Select this option to assign multiple profiles to different sets of devices using Custom Device Profile Mapping.
Select ADE ProfileSelect a profile which will be applied to the devices during enrollment. This will be applicable only if Profile Assignment Scope is selected as All Devices. (or) Default Assignment Action is selected as Allow
Default Assignment Action
Allow - Select this option to allow default ADE profile assignment.
Deny - Select this option to restrict default ADE profile assignment.
This will be applicable only if Profile Assignment Scope is selected as Device-specific Assignment.
Table EntriesIf the Default Assignment Action is configured as either Allow or Deny, the corresponding device list must be defined in the table section. During device list upload, the administrator should be prompted to select an ADE Profile. The specified devices will then be automatically associated with and enrolled using the selected ADE Profile, ensuring the appropriate enrollment configuration is applied to those devices.

3. Next, assign the devices to SureMDM by following the steps added here.

alt text

alt text

4. Select the created ADE Server and click Push the Config. 

alt text

note

To initiate ADE enrollment, the device must be wiped or factory reset.